Cisco Catalyst SD-WAN Manager (CVE-2026-20122 & CVE-2026-20128) Flaws Exploited
ID: cb3bdf91-2908-5e6d-8d00-459c2cf04181
STIX ID: report--cb3bdf91-2908-5e6d-8d00-459c2cf04181
Feed Name: SOCRadar Blog
Cisco confirmed active exploitation of two vulnerabilities in Catalyst SD-WAN Manager (CVE-2026-20122 — arbitrary file overwrite via the vManage API, and CVE-2026-20128 — DCA credential exposure). Public and third-party reporting indicates high-volume exploitation attempts and web shell deployment; Cisco provides fixed releases per version train and states there are no workarounds, so organizations should prioritize patching, restrict management/API exposure, and treat internet-facing instances as potentially compromised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
